ie8 fix
madison

Threat Chaos

Richard Stiennon

Insiders, you gotta watch 'em

By | November 12, 2007, 3:19pm PST

It is a pretty common theme of my Cyber Crime Scenario presentation that insiders are a risk. The more so because markets for data, especially credit card info, are making it possible for just about anay knowledge worker with access to data to rob you.

But the real damage comes from the clever insider that figures out your business operations and a way to hack them. Accounting fraud has been around since the invention of commerce and many controls have been put in place to lower the risk associated with white collar crime. Using IT resources is just an extension of what has gone before.

The latest case: an insider at an online poker site figures out how to beat the house using his access to the internal systems. Cost to the company? $1.6 million.

The company’s response seems appropriate. They figured out every player that had lost money while playing against the insider’s hands and reimbursed them. I am interested in what the cost to Absolute Poker was in lost revenue due to loss of trust in the honesty of their systems. (Just a reminder to US citizens that online gaming is illegal for them).

When I was a white hat hacker for PricewaterhouseCoopers there was one realization that came quickly. Given three or four days insider access to any organization we could figure out how to steal from them. Controls must extend beyond the financial systems and be deployed systemically throughout IT.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Disclosure

Richard

http://blogs.zdnet.com/threatchaos/?page_id=455

Biography

Richard

A former ZDNet blogger, Richard Stiennon is an industry consultant. Most recently he was Chief Marketing Officer for Fortinet, Inc., the largest privately held security vendor. prior to that he was Chief Research Analyst at IT-Harvest. And before creating IT-Harvest, he was VP of threat research for Webroot Software, Inc. the leading commercial anti-spyware solution.

Previously, Richard was VP Research at Gartner, Inc. where he covered security topics including firewalls, intrusion detection, intrusion prevention, security consulting and managed security services for the Security and Privacy group. He is a holder of Gartner's Thought Leadership award for 2003 and was named "One of the 50 most powerful people in Networking" by NetworkWorld magazine. His speaking engagements have included conferences and meetings throughout North and South America, Hawaii, Tokyo, Tel Aviv, Istanbul, Milan, Munich, Hannover, Madrid, London, and Cannes.

The discussion hasn’t started yet. Why don’t you begin it?

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix